Payment Gateway of Stripe for WooCommerce <= 5.0.7 - Missing Authorization
medium
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.0.7
- Fixed in:
- 5.0.8
- Disclosed:
- May 12, 2026
CVE-2026-45217 on NVD →
Stripe Payment Gateway for WooCommerce [payment-gateway-stripe-and-woocommerce-integration] < 3.8.0
unknown
Update the WordPress Stripe Payment Gateway for WooCommerce plugin to the latest available version (at least 3.8.0).
Francesco Carlucci discovered and reported this SQL Injection vulnerability in WordPress Stripe Payment Gateway for WooCommerce Plugin. This could allow a malicious actor to directly interact with your d...
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.0
- Disclosed:
- Jan 19, 2024
Stripe Payment Gateway for WooCommerce [payment-gateway-stripe-and-woocommerce-integration] < 3.8.0
unknown
[en] The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unau...
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.0
- Disclosed:
- Jan 19, 2024
CVE-2024-0705 on NVD →
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
critical
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthent...
- CVSS:
- 9.8
- Affected:
- up to 3.7.9
- Fixed in:
- 3.8.0
- Disclosed:
- Jan 18, 2024
CVE-2024-0705 on NVD →
Stripe Payment Gateway for WooCommerce [payment-gateway-stripe-and-woocommerce-integration] < 3.8.0
unknown
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthent...
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.0
- Disclosed:
- Jan 18, 2024
Stripe Payment Gateway for WooCommerce [payment-gateway-stripe-and-woocommerce-integration] < 3.7.8
unknown
[en] The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows unauthenticated attackers to log in as users wh...
- Affected:
- up to 3.7.8
- Fixed in:
- 3.7.8
- Disclosed:
- Aug 31, 2023
CVE-2023-3162 on NVD →
Stripe Payment Gateway for WooCommerce [payment-gateway-stripe-and-woocommerce-integration] < 3.8.0
unknown
[en] The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_callback_handler function in versions up to, and including, 3.7.9. This makes it possible for unauthenticated attackers to modify the order status of arbitra...
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.0
- Disclosed:
- Aug 18, 2023
CVE-2023-4040 on NVD →
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Missing Authorization to Arbitrary Order Status Modification
medium
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_callback_handler function in versions up to, and including, 3.7.9. This makes it possible for unauthenticated attackers to modify the order status of arbitrary Wo...
- CVSS:
- 5.3
- Affected:
- 3.7.9 – 3.7.9
- Fixed in:
- 3.8.0
- Disclosed:
- Aug 17, 2023
CVE-2023-4040 on NVD →
Stripe Payment Plugin for WooCommerce <= 3.7.7 - Authentication Bypass
critical
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows unauthenticated attackers to log in as users who hav...
- CVSS:
- 9.8
- Affected:
- up to 3.7.7
- Fixed in:
- 3.7.8
- Disclosed:
- Aug 1, 2023
CVE-2023-3162 on NVD →
Stripe Payment Plugin for WooCommerce <= 3.5.9 - Reflected Cross-Site Scripting
medium
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions up to, and including, 3.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- up to 3.5.9
- Fixed in:
- 3.6.0
- Disclosed:
- Jun 7, 2021
Stripe Payment Gateway for WooCommerce [payment-gateway-stripe-and-woocommerce-integration] < 3.6.0
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Stripe Payment Gateway for WooCommerce plugin (versions <= 3.5.9).
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Jun 7, 2021
Stripe Payment Gateway for WooCommerce [payment-gateway-stripe-and-woocommerce-integration] < 3.6.0
unknown
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions up to, and including, 3.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Jun 7, 2021
Stripe Payment Gateway for WooCommerce [payment-gateway-stripe-and-woocommerce-integration] < 3.6.0
unknown
The plugin did not sanitise or escape the page parameter before outputting back in an attribute, leading to a reflected Cross-Site Scripting issue
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database